complyeah
External Pentest

External pentest evidence for SOC 2 and ISO 27001.

Run an authorized external assessment on a domain you control. Get a control-mapped report, concrete remediation, and a retest trail for every fix. Human review is available when your auditor requires it.

Verified ownership · Attributable traffic · External-only scope · Non-destructive testing

What gets tested

complyeah examines the public attack surface of a domain you control: TLS, headers, cookies, DNS, exposed files and secrets, discovered endpoints, known vulnerability patterns, and read-only agentic checks where appropriate.

  • Ownership and authorization are checked before the run and again by the worker.
  • Testing is external, attributable, throttled, and constrained to the verified scope.
  • Every finding includes evidence, severity, a practical fix, and applicable SOC 2 or ISO 27001 controls.

Free posture or comprehensive pentest

A free posture snapshot gives you a useful baseline at $0. The $50 comprehensive external pentest adds deeper coverage, the auditor-ready report and certificate, and one full retest within 60 days. Unused one-time purchase credits remain valid for 12 months.

Continuous when one point in time test is not enough

Continuous costs $49 per verified domain each month or $490 annually. It includes three posture scans and five agent runs with up to ten workflow nodes each, plus one external pentest each quarter that is available immediately, with a maximum of four in a rolling year.

Scope and limitations

This is an external assessment of the authorized public surface. It is not source-code review, internal-network testing, social engineering, destructive exploitation, or a guarantee of an audit outcome. Optional authenticated authorization testing runs only when the customer explicitly supplies and authorizes bounded test identities.

Test the product you actually shipped.

Start with a free posture snapshot, buy one external pentest, or monitor security and Agent Readiness continuously.